Junglewise Threat Intelligence

CVE-2026-30863: Parse Server JWT audience validation bypass in authentication adapters

CVE-2026-30863 · Severity: medium · CVSS 4 · Published 2026-03-09

Technologies: Parse Community Parse Server. Vendors: Parse Community.

Executive brief

Parse Server is a backend framework that handles user authentication through integrations with Google, Apple, and Facebook. The vulnerability allows attackers to bypass JWT audience validation and authenticate as any user by reusing valid tokens issued for different applications, potentially gaining unauthorized access to user data and application functionality.

Technical details

The vulnerability is an authentication bypass caused by insufficient JWT audience claim validation in the Google, Apple, and Facebook authentication adapters. When the configuration options are not set (clientId for Google/Apple, or appIds for Facebook), JWT verification silently skips audience validation instead of rejecting the token. An attacker with a validly signed JWT from any application can authenticate as any user on the target server. The vulnerability is network-accessible with no authentication or user interaction required. Patches are available in Parse Server 9.5.0-alpha.11 and 8.6.10, which make configuration options mandatory and enforce proper audience validation.

Affected products

  • Parse Community Parse Server before 8.6.10; 9.0.0-alpha.1 before 9.5.0-alpha.11

Timeline

  • 2026-03-07: disclosed
  • 2026-03-09: patched: Parse Server 9.5.0-alpha.11 and 8.6.10 released

References